Umbra Wiki technique technique/T1584.004
Back to wiki

T1584.004 — Server

provenance: imported · ATT&CK: T1584.004

T1584.004: Server

MITRE ATT&CK® Enterprise technique

Tactics Resource Development
Platforms PRE
Permissions required
Version 1.2
Parent technique T1584

Description

Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an operation. During post-compromise activity, adversaries may utilize servers for various tasks, including for Command and Control.(Citation: TrendMicro EarthLusca 2022) Instead of purchasing a Server or Virtual Private Server, adversaries may compromise third-party servers in support of operations.

Adversaries may also compromise web servers to support watering hole operations, as in Drive-by Compromise, or email servers to support Phishing operations.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1584/004
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/